DRI2026 took place in Jacksonville, Florida, from 22 to 25 February. Jacksonville offered the perfect start to the conference year, with the bright and airy venue of the Hyatt Regency providing the perfect setting. Following tradition, the DRI Foundation team spent the Saturday before the conference volunteering, this year with the Volunteers of America Florida charity. It so happened to be one of the warmest days of the year so far, and perfect for donning work boots, paintbrushes, drills, hammers, and saws.
However, as Winter Storm Hernando threatened to turn the sunshine into snow, attendees were grateful for the indoor heat as DRI2026 got underway.
The themes of this year’s conference were symptomatic of an economy that has become structurally interruption-prone and, as a result, the programme repeatedly returned loosely to five topics: supply chain resilience, third-party risk management (TPRM), cyber security, operational resilience, and the governance of AI and other emerging technologies. Sessions repeatedly confirmed the tight interlocking of these disciplines which have previously been considered as disparate areas.
It is clear that supply chain resilience has become an intrinsic part of operational resilience; operational resilience has become increasingly dependent on better data and technology governance; and both are exposed to cyber and geopolitical shocks that now travel through entire business ecosystems rather than just a single organization.
That framing was explicit in the opening plenary which spoke to how an organization’s business continuity plans (BCPs) were only as strong as their suppliers’ BCPs. The presentation’s primary argument was that ‘continuity-critical’ suppliers should be identified by impact and substitutability rather than by spend. This is something business continuity and resilience practitioners have practised for years, but it is now becoming realised in boardrooms, too.
This mirrors the way regulators and central banks are increasingly thinking about resilience, especially in finance, where firms are mandated to map the people, processes, technology, and third parties that underpin their defined important business services. The Bank of England’s operational resilience regime required firms to meet their tolerances by 31 March 2025, and in its 2026 supervisory priorities it said firms should now embed operational resilience into strategic decision-making rather than treat it as a compliance necessity.
That emphasis on interdependence was reinforced elsewhere in the programme. A powerful case study presentation showed how an organization had built a centralised but scalable TPRM model across five independently managed operating companies, connecting procurement, legal, security, and finance under a shared resilience framework. Later, a further presentation stressed that resilience is not achieved by onboarding due diligence alone but by lifecycle governance, service level oversight, incident obligations, and exit provisions.
Outside the world of business continuity, global regulations are also moving a similar way. The Basel Committee published its final principles for the sound management of third-party risk in late 2025, explicitly linking nth party exposure, concentration risk, and supply chain dependencies to banks’ ability to withstand and recover from operational disruption. In Europe, the Digital Operational Resilience Act, DORA, has applied since 17 January 2025, and regulators have already begun designating major technology firms as critical ICT third party providers to the financial sector.
However, while regulatory jargon can be difficult to put into practice, particularly for those not used to implementing operational resilience, the speakers at DRI2026 were able to effectively translate that regulatory logic into practitioner language: contracts, governance forums, supplier participation in exercises, and better dependency data.
Operational resilience – it’s living, it’s dynamic – and its pushing strategic growth
The presentations on operational resilience were equally contemporary. One presentation showed how resilience is losing its reputation as a defensive control and is fast becoming an enabler of strategic growth. Other presentations talked about how the ability to monitor, mine, and action data was pushing BCPs towards a dynamic data product rather than a static document that is updated annually. Further presentations added AI into the mix and showed how AI-enhanced incident tools can also be employed to add further efficiencies to incident management and greater realism to training and exercising.
AI is finally finding the ‘right place’ in resilience strategies
AI-themed presentations at DRI2026 were notable because they were not techno-utopian, i.e. a total technology takeover of business continuity and resilience processes by AI. Presentations focused on the relationship among models, regulations, applications, and suppliers. One presentation spoke about using AI as a tool to speed BIA, planning, and after-action reviews, but did so through a lens of human oversight and trust while another suggested that AI could pressure-test recovery assumptions and map dependencies from messy data but should not replace practitioner judgement. The implication from all these sessions was sensible: AI is becoming part of the resilience stack, but it is also a new dependency that must itself be governed.
That is closely aligned with external policy thinking. NIST’s Generative AI Profile, published in July 2024 as a companion to the AI Risk Management Framework, urged organizations to manage AI risk across the full lifecycle and to align governance, validation, and human oversight with business objectives. In policy circles, the debate has widened further, from model risk to infrastructure dependence. The Brookings Institution argued in early 2026 that ‘AI sovereignty’ is increasingly about the ability to make independent decisions regarding critical AI infrastructure, data and deployment, and is far from being purely about model development. For resilience practitioners, that means AI is both an efficiency tool and a fresh concentration risk.
Delving into supply chain resilience
Supply chain resilience was one of the most consequential themes at DRI2026. The opening plenary made that explicit by showing the importance of placing procurement as an integral part of business continuity. Other presentations showed how third-party risk becomes operationally meaningful only when it is tiered, onboarded, and monitored in business workflows, with other speakers stressing that resilience requires audit rights, disaster recovery, and business continuity plan clauses, incident obligations, termination protections, and transition safeguards. It became clear through presentations that there is now a clear, missing connective tissue: once dependencies are visible in live data, supply chain risk can be assessed as part of event response rather than – or in most cases, as well as – an annual paperwork exercise.
Supply chains have not been a manufacturing-only issue for some time now. Conference presentations sessions by manufacturers and retailers showed how downtime, shortages, and external dependencies can quickly become critical problems for customers; not only damaging reputation but also destroying sales figures and company value. However, the most revealing examples came from presentations by services organizations: they are discussing managed services, cloud providers, digital tooling, outsourced operations, legal terms, internal data architecture, and global incident coordination. The supply chain in 2026 is as much a map of contracts and software dependencies as it is of containers and components.
Academic and policy literature increasingly supports this broader view, which includes the DRI Professional Practices. Professional Practice Three: Business Impact Analysis requires dependencies to be documented across processes, technology, supply chain, and third parties. Meanwhile, Professional Practice Four: Continuity Strategies explicitly calls for identification of supply chain issues affecting both suppliers and customers and recommends potential strategies in light of the results of the risk assessment and the BIA. Also, Professional Practice Two: Risk Assessment requires risk identification across workforce, supply chain, cyber security, IT, legal, and regulatory dimensions. In other words, DRI’s own body of knowledge already treats supply chain resilience as a multi-resource dependency problem rather than a narrow logistics function.
The external evidence points the same way. The OECD’s Supply Chain Resilience Review 2025 argues for agile, adaptable, and aligned supply chains, and warns against hastily-introduced relocalisation strategies. An IMF working paper from 2025 similarly finds that while diversification of import sources can mitigate trade shocks, they do not come without efficiency trade-offs. A further National Bureau of Economic Research (NBER) work reaches a similar conclusion, showing that diversification can outperform some reshoring strategies in promoting resilience. DRI2026’s framing therefore appears to be well judged.
The fact that this thinking is emerging now is particularly critical due to current global events. Shipping and trade routes are being actively exposed to conflict and coercion. As of March 2026, reports speak of fresh disruption in Gulf and Red Sea shipping linked to the Iran crisis, with rerouting, fuel redistribution, and surcharges rippling across carriers and ports. Even before those events, the global trade system was contending with Red Sea insecurity, policy uncertainty, and a proliferation of trade restrictions.
Cyber pushes the case for supply chain resilience even further
Cyber has made the case for supply chain resilience even stronger. The ransomware tabletop in the opening session at DRI2026 explicitly posed the question of what happens when a cyber incident destroys recovery assumptions and spreads through the supply chain. Another presentation by a healthcare resilience professional also demonstrated that cyber downtime directly links to patient safety and noted the need to understand the loss of connected technologies, not merely core clinical systems.
Supply chain resilience is also now inseparable from operational resilience regulation. DORA’s focus on ICT third party providers, the Basel Committee’s TPRM principles, and the Bank of England’s insistence on mapping important business services (and third parties) all reflect a common proposition: firms do not fail alone – they fail through networks. DRI2026’s programme with significant focus on supplier management therefore demonstrates a delayed convergence between business continuity practice and regulatory reality. What practitioners used to treat as vendor management has fast become a core resilience capability.
The fact that third-party risk management has become so integral to business continuity planning was recognised by DRI in an announcement during the opening plenary that DRI is to introduce a new supply chain management course and certification to help practitioners understand the importance of the new era of supply chain management and organizational interdependencies.
Final thoughts
The practical message for practitioners is straightforward, although far from simple. Firstly, supplier management no longer needs to go deeper into the chain – it has to. Criticality is now defined by service impact and substitutability, not by spend or convenience – which is why buy-in and support from senior management is critical. Secondly, the contract process requires more rigour. Resilience clauses should not be boilerplates, and they should include legal test rights, incident obligations, transition support, sub-outsourcing visibility (or even possibility!), and meaningful service levels. Thirdly, resilience data needs to become operational – and not just sit in shared drives. There is no excuse now for not being able to collect and mine large quantities of data. Dependency mapping should connect suppliers, systems, business services, locations, and people in ways that support event response. Finally, supplier relationships matter. A weak – or even adversarial – procurement model provides an unsuitable base for crisis collaboration. Much of DRI2026’s content was really an argument for relationship-based governance backed by evidence and enforceable terms.
Those conclusions align closely with the DRI Professional Practices. Professional Practice Two: Risk Assessment calls for entity-wide collaboration across supply chain management, cyber security, legal, and other stakeholders. Professional Practice Three: Business Impact Analysis requires identification and documentation of internal and external dependencies. Professional Practice Four: Business Continuity Strategies explicitly covers supply chain strategies, third party services, cloud computing, and cost-benefit analysis. Professional Practice Five: Incident Preparedness and Response extends the frame to external agencies and response resources, while Professional Practice Eight emphasises exercise, assessment, and maintenance. In that sense DRI2026 demonstrated how the Professional Practices could be best applied in a world of cloud concentration, AI adoption, geopolitical friction, and ecosystem risk.
The author
Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.







